Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-97907

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Bluetooth: btrtl: Don&amp;#39;t leak return code when parsing firmware format v2<br /> <br /> When key_id from chip is zero, rtlbt_parse_firmware_v2() intentionally<br /> ignores all security headers. However, the implementation simply breaks<br /> from a switch statement and leaks uninitialized return code `rc&amp;#39; (if the<br /> first section is a security one) or the previous section&amp;#39;s `rc&amp;#39;.<br /> <br /> Fix it by really skipping a loop with `continue&amp;#39;. For consistency and<br /> readability, also do the same for the default case.

Impacto